Insight

The EU Data Act: connected product data, cloud switching and the dates that matter

The Data Act has applied since 12 September 2025. It gives users of connected products rights to the data those products generate, requires new products to be designed for data access, restricts unfair data-sharing terms between businesses and makes it easier to switch cloud providers. Its obligations arrive in stages.

Published by Somnium Digital

A wireframe of the Insight page: headline, supporting sections and a single call to action. Insight The EU Data Act Get in touch 01 What the Data Act is… 02 Connected products an… 03 Design obligations fr…

What the Data Act is for

Regulation (EU) 2023/2854, the Data Act, is part of the EU data strategy. Where the GDPR protects personal data, the Data Act deals with who may access and use data generated by connected products and related services, whether that data is personal or not. It also addresses contract terms for data sharing between businesses, access to data by public bodies in exceptional situations, and switching between data processing services such as cloud providers.

Because it is a regulation, it applies directly across the EU. It entered into force in January 2024 and has applied generally since 12 September 2025, with some obligations phased in later.

For digital teams, the Data Act matters in two ways. Companies that make connected products, from industrial machines to smart home devices and vehicles, have to build data access into their products and apps. Companies that buy or sell cloud and software services gain and owe new rights around switching and data portability.

Connected products and related services

A connected product is an item that obtains, generates or collects data about its use or environment and can communicate that data, for example over a network. A related service is a digital service, such as an app, connected to the product so that without it the product could not perform one of its functions, or that is later connected to add to or adapt the product’s functions.

Users of such products, whether consumers or businesses, get a right to access the product data and related service data they generate, and to have that data shared with a third party of their choice. Data holders must make readily available data accessible without undue delay, free of charge to the user, and in a comprehensive, commonly used and machine-readable format where relevant.

There are safeguards. Trade secrets can be protected through agreed measures, and in exceptional cases disclosure can be refused where serious economic damage is likely. Designated gatekeepers under the Digital Markets Act cannot be third-party recipients of data shared this way. Data recipients may not use the data to develop a competing product.

Design obligations from September 2026

The obligation to design and manufacture connected products, and to design and provide related services, so that data is accessible to the user by default, easily, securely and where relevant directly, applies to products placed on the market and related services from 12 September 2026 onwards.

Before a contract is concluded, the seller, renter or provider must also give users clear information, including the type, format and estimated volume of data the product can generate, whether data is generated continuously and in real time, where and how long it is stored, and how the user can access, retrieve or erase it.

For product teams, this is an architecture question rather than a legal footnote. Data access needs to be part of the device firmware, the cloud back end, the customer portal or app, and the documentation, with identity checks so data only reaches the right user or authorised third party.

Inventory
Which data each product and related service generates, where it goes and in what format.
Access route
Direct on-device access, a portal, an API or export, with authentication and logging.
Third-party sharing
A way for users to authorise a named recipient, with terms and compensation rules for business recipients.
Pre-contract information
Clear data descriptions in product pages, sales documents and rental agreements.

Unfair terms in business data contracts

The Data Act makes certain contractual terms on data access and use, unilaterally imposed on another business, not binding if they are unfair. It lists terms that are always unfair, such as excluding liability for intentional acts or gross negligence, and terms presumed unfair, such as inappropriately limiting remedies or preventing a party from using data it contributed.

These rules apply to contracts concluded after 12 September 2025. For contracts concluded on or before that date that are of indefinite duration or expire at least ten years after January 2024, they apply from 12 September 2027. Businesses with long-running data sharing arrangements should review them before that date.

Switching cloud and data processing services

Chapter VI requires providers of data processing services, which includes cloud infrastructure, platforms and software offered as a service, to remove obstacles to switching. Customers must be able to switch to another provider or to their own infrastructure, and contracts must set out switching rights clearly.

The maximum notice period to start the switching process is two months. After that, a transitional period of up to 30 calendar days applies, which can be extended where switching within that time is technically unfeasible. Customers must also get a period of at least 30 days to retrieve their data after the transition.

Switching charges are being phased out. Until 12 January 2027, providers may charge reduced switching charges that do not exceed their direct costs. From that date, switching charges are no longer allowed. Providers must also publish information about their interfaces, data formats and any known restrictions that could affect switching.

What businesses should do now

Manufacturers of connected products should map data flows, design user access into new products placed on the market, prepare pre-contract information and set up a process for handling user and third-party data requests, including trade secret protection and compensation terms for business recipients.

Buyers of cloud and software services should review contracts for switching terms, notice periods, data export formats and charges, and plan exit routes for critical systems. Providers should update contracts, documentation and export tooling so switching is possible in practice, not only on paper.

Anyone with long-term data sharing contracts should check them against the unfair terms rules before September 2027. National authorities enforce the Data Act, so penalties and procedures depend partly on member state law. This article is a general overview and not legal advice.

Questions

When did the Data Act start to apply?

It has applied generally since 12 September 2025, with some obligations phased in later.

Does the Data Act only cover personal data?

No. It covers data generated by connected products and related services whether personal or not, while the GDPR continues to apply to personal data.

What applies from 12 September 2026?

The obligation to design connected products and related services so data is accessible to users by default applies to products and services placed on the market from that date.

Can users share their product data with another company?

Yes. Users can ask the data holder to share data with a third party of their choice, with safeguards and exclusions such as for designated gatekeepers.

How long can a cloud provider make customers wait to switch?

The maximum notice period is two months, followed by a transitional period of up to 30 calendar days that can be extended where technically unfeasible.

When do cloud switching charges end?

From 12 January 2027 switching charges are not allowed. Before that, only reduced charges not exceeding direct costs are permitted.

Do the unfair terms rules apply to old contracts?

For certain long-term contracts concluded on or before 12 September 2025, they apply from 12 September 2027.

Where this sits in what we do

This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.

Building data access into a connected product?

We design customer portals, APIs and export tooling that give users and authorised third parties access to product data securely and with proper records.

Get in touch

Tell us what you are trying to change

Describe the problem rather than the service — the two frequently differ, and working out which is which is the useful part of a first conversation. We reply within one working day, and if it is outside what we do well you will hear that in the reply rather than after a call.

We use what you send to reply to you. Nothing else, and no list.

WhatsApp